If you are based in the EU, UK, or another country, your personal data is transferred to and stored in the United States, where different privacy laws apply, though Eventbrite states it uses EU-approved Standard Contractual Clauses to make these transfers lawful.
This analysis describes what Eventbrite's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
EU and UK users' data is processed under US law once transferred, and the adequacy of Standard Contractual Clauses as a transfer mechanism is subject to ongoing regulatory and legal scrutiny.
Interpretive note: The adequacy of Standard Contractual Clauses as a transfer mechanism depends on supplementary Transfer Impact Assessments whose content is not disclosed in the policy, and the status of any EU-US Data Privacy Framework participation is not confirmed.
The updated terms expand the circumstances under which your email address is shared with event organizers. Previously, Eventbrite shared email addresses only with organizers of events you registered for. Under the revised policy, your email is also shared with organizers if you elect to receive their marketing communications through the Eventbrite platform. The policy clarifies that organizers own the data relationship with you for these marketing subscriptions, while Eventbrite processes the consent and delivery on their behalf.
View change record →The updated terms establish formal procedures for UK-based users to lodge data protection complaints directly with Eventbrite via privacy@eventbrite.com, with assurance that complaints will follow ICO guidelines. The revised policy also confirms that all users have the right to escalate complaints to their national data protection authority or applicable regulator if they believe Eventbrite has violated privacy laws or has not adequately addressed their request. Previously, the policy referenced a Data Privacy Framework Notice but did not specify complaint procedures or regulatory escalation pathways. These additions clarify existing legal rights under UK and EU data protection law rather than creating new consumer obligations.
View change record →Previous version had empty excerpt; current version now explicitly mentions Standard Contractual Clauses and EU data protection mechanisms.
View full change record →EU and UK users' personal data is transferred to the United States for processing, meaning it is subject to US legal access frameworks, though Eventbrite states it uses Standard Contractual Clauses as a safeguard for these transfers.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"If you are located outside the United States, please be aware that information we collect will be transferred to and processed in the United States. By using our services or providing us with any information, you consent to this transfer, processing, and storage of your information in the United States, where the data protection laws may be different from those in your country. We rely on mechanisms such as Standard Contractual Clauses approved by the European Commission to transfer data from the EU/EEA and UK to the United States.Excerpt from Eventbrite's Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
EU and UK users' data is processed under US law once transferred, and the adequacy of Standard Contractual Clauses as a transfer mechanism is subject to ongoing regulatory and legal scrutiny.
EU and UK users' personal data is transferred to the United States for processing, meaning it is subject to US legal access frameworks, though Eventbrite states it uses Standard Contractual Clauses as a safeguard for these transfers.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Eventbrite.